
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began

A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began

Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline

President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed

A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to

Nikkei disclosed a Microsoft 365 account breach that sent 9,000 spoofed emails to contacts, plus a separate cloud intrusion exposing

Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.

Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it

A ten-country police operation seized KillSec’s servers and leak site, arrested a suspected 16-year-old ringleader, and recovered over 110TB of

Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly

Sucuri found a WordPress backdoor, SC, that persists across eight file, database, and memory locations and rebuilds itself when any
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.